The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Using temporary autoboot for system patching

Prev Next

Temporary autoboot is a maintenance feature that can be enabled regardless of your primary policy configuration, including environments already using TPM autoboot.

This feature temporarily bypasses TPM PCR validation and switches to a less secure, static on-disk key for authentication. Its primary purpose is to prevent PBA from being triggered during system maintenance, such as when rolling out a firmware or OS patch that you know will change TPM measurements.

This allows administrators to perform major updates without causing user disruption. For details on enabling and using this feature, see Enable or disable temporary automatic booting.